Floosietek FTGate PRO SMTP RCPT TO Buffer Overflow Vulnerability
BID:7508
Info
Floosietek FTGate PRO SMTP RCPT TO Buffer Overflow Vulnerability
| Bugtraq ID: | 7508 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2003 12:00AM |
| Updated: | May 06 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Dennis Rand of Infowarfare.dk. |
| Vulnerable: |
Floosietek FTGatePro 1.22 (1328) |
| Not Vulnerable: |
Floosietek FTGatePro 1.22 (1330) |
Discussion
Floosietek FTGate PRO SMTP RCPT TO Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported for Floosietek FTGate PRO mail server. The vulnerability exists when the mail server attempts to process overly long SMTP 'Rcpt To' arguments. Due to the nature of this vulnerability it may be exploited to execute attacker-supplied code with the privileges of the SYSTEM user.
This vulnerability was reported for FTGate PRO 1.22 Hotfix(1328). It is likely that previous versions are also affected.
A buffer overflow vulnerability has been reported for Floosietek FTGate PRO mail server. The vulnerability exists when the mail server attempts to process overly long SMTP 'Rcpt To' arguments. Due to the nature of this vulnerability it may be exploited to execute attacker-supplied code with the privileges of the SYSTEM user.
This vulnerability was reported for FTGate PRO 1.22 Hotfix(1328). It is likely that previous versions are also affected.
Exploit / POC
Floosietek FTGate PRO SMTP RCPT TO Buffer Overflow Vulnerability
The following proof of concept has been supplied:
The following proof of concept has been supplied:
Solution / Fix
Floosietek FTGate PRO SMTP RCPT TO Buffer Overflow Vulnerability
Solution:
The vendor has addressed this issue in the current hotfix(1330). Existing customers are strongly advised to download it through the WebAdmin UI.
Solution:
The vendor has addressed this issue in the current hotfix(1330). Existing customers are strongly advised to download it through the WebAdmin UI.
References
Floosietek FTGate PRO SMTP RCPT TO Buffer Overflow Vulnerability
References:
References:
- FTGate Homepage (Floosietek)
- Multiple Buffer Overflow Vulnerabilities Found in FTGate Pro Mail Server v. 1.22 (Dennis Rand)
- Multiple Buffer Overflow Vulnerabilities Found in FTGate Pro Mail Server v. 1.22 (Dennis Rand
)